Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

EU AI Act 2026: a practical compliance guide for businesses

Understand AI Act roles, risk classes, the 2026–2028 timeline, AI literacy, transparency, documentation, human oversight and cybersecurity.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
12 July 2026
READING TIME
17 min read
TOPIC
AI Security
EU AI Act 2026: a practical compliance guide for businesses

The EU AI Act in 2026 is becoming an operating programme for businesses. Some obligations already apply, further transparency rules apply from 2 August 2026, and the high-risk timeline has been affected by the political agreement on the AI Omnibus.

In short: inventory AI use, determine your role, classify risk, provide AI literacy, document suppliers and data, implement human oversight, monitoring and cybersecurity. Buying a model from a large provider does not transfer every obligation to that provider.

Legal and implementation status: 12 July 2026. This guide distinguishes Regulation 2024/1689 from amendments politically agreed in May 2026. Check the latest consolidated law and Commission guidance before legal decisions. This is information, not legal advice.

What is the AI Act?

Regulation (EU) 2024/1689 creates harmonised rules for placing AI systems and general-purpose models on the market, putting systems into service and using them in the Union. It covers prohibited practices, high-risk systems, transparency, GPAI, market supervision and enforcement.

The regime is use-case driven. The same language model might draft low-risk marketing copy or become part of a recruitment ranking system. Purpose, context, operator role and actual use matter.

Determine the company’s role first

An organisation may be a provider, deployer, importer, distributor, product manufacturer or an actor that substantially modifies a system or changes its intended purpose.

A company buying a chatbot will often be a deployer. Selling a solution under its own name, materially modifying it or assigning a new high-risk purpose may alter that analysis. Supplier contracts do not replace role classification.

The four risk levels

Unacceptable risk

Defined practices have been prohibited since 2 February 2025. Commission examples include harmful manipulation, some social scoring, untargeted scraping to build facial-recognition databases and specified emotion-recognition and biometric uses. Each prohibition has legal conditions and exceptions; a summary list is not sufficient for classification.

High risk

Potential areas include employment, education, critical infrastructure, access to essential services, biometrics, migration and justice. Providers face requirements involving risk management, data, logs, technical documentation, deployer information, human oversight, accuracy, robustness and cybersecurity.

Deployers also have responsibilities, including use consistent with instructions, appropriate human oversight and monitoring. Exact obligations depend on system and role.

Transparency risk

In defined situations people must be told they are interacting with AI. Article 50 also addresses machine-readable marking or disclosure for some synthetic content and deepfakes. These rules apply from 2 August 2026. Our guide to the EU code for AI-generated content labelling covers that layer.

Minimal or no risk

Many uses do not receive the high-risk regime. Other law still applies, including data protection, consumer, employment, trade-secret and product-safety rules.

AI Act timeline for 2026–2028

According to the European Commission’s current implementation page:

DateMilestone
1 August 2024AI Act entered into force
2 February 2025prohibitions and AI literacy started to apply
2 August 2025governance and GPAI obligations started to apply
2 August 2026most remaining rules, including transparency, apply subject to exceptions
2 December 2027agreed Omnibus date for specified high-risk areas
2 August 2028agreed date for high-risk systems embedded in regulated products

The 2027–2028 dates reported by the Commission follow a political agreement reached on 7 May 2026. Organisations should track completion of the legislative process and the consolidated text rather than rely on an old slide or blog.

AI literacy already applies

Article 4 requires measures to ensure a sufficient level of AI literacy among staff and other persons operating systems on the organisation’s behalf. One generic course is unlikely to fit every role.

Training should reflect technical knowledge, experience, use context and affected persons. A copywriting user, recruiter relying on AI output and administrator connecting an agent to email need different preparation.

Retain audience, date, content and competence evidence. Cover limitations, error, privacy, prompt injection, escalation and the danger of blindly approving output.

What businesses should do now

1. Build an AI inventory

Record owner, purpose, legal role, model, provider, data, integrations, users, output recipients and risk status. Include employee-purchased services and AI features embedded in existing SaaS. Use a practical AI model and system registry.

2. Classify each use

Determine whether it is an AI system, the organisation’s role, and whether the use is prohibited, high-risk or subject to transparency. Document reasoning and sources. Absence from a high-risk list does not remove other law and operational risk.

3. Control suppliers and contracts

Collect terms covering data use, region, retention, subprocessors, model versioning, logs, export, deletion, SLA and incident handling. Determine who supplies the documentation the business needs and what happens after material model change.

4. Design real human oversight

Human-in-the-loop cannot be a decorative button. The reviewer needs skill, time, evidence and genuine authority to reject output. The interface should expose sources, uncertainty and action impact, while performance targets must not force automatic approval.

5. Monitor and document

Version models, prompts, tools, RAG sources and evaluations. Log material decisions while minimising personal data. Define suspension thresholds, reporting routes and post-market monitoring ownership where applicable.

6. Test cybersecurity

High-risk systems require appropriate accuracy, robustness and cybersecurity, while lower-risk deployments still need protection. Assess prompt injection, RAG isolation, agent permissions, secrets, dependencies, suppliers and incident response. Use the complete AI and LLM security audit guide.

Evidence worth maintaining

  • AI use and supplier inventory;
  • role and risk classification;
  • rights, privacy and security impact assessment;
  • use instructions and intended-purpose boundaries;
  • AI literacy evidence;
  • evaluation and test results;
  • human-oversight procedure;
  • model, prompt and data change history;
  • monitoring, incidents and corrective action;
  • retirement and data-export plan.

Documentation must change with the system. A spreadsheet prepared once will not detect a model update, new connector or broader agent role.

Common implementation mistakes

  1. “We only consume an API, so the Act does not apply.” Deployers may have obligations.
  2. “The provider is compliant, therefore our process is compliant.” Use, oversight and data remain deployment concerns.
  3. No inventory: an unseen system cannot be classified.
  4. Labelling all AI high-risk: this destroys prioritisation.
  5. One training for every role.
  6. Human review without real authority or information.
  7. No change management for model updates.

30-day checklist

  • Appoint an AI governance owner.
  • Discover use through SSO, spend, repositories and interviews.
  • Assign a business owner to every system.
  • Determine role and preliminary risk class.
  • Escalate potentially prohibited practices immediately.
  • Identify Article 50 systems.
  • Document the AI literacy programme.
  • Collect supplier contracts and configurations.
  • Map personal and confidential data and access.
  • Define human oversight and stop conditions.
  • Plan quality and security testing.
  • Establish quarterly change review.

Frequently asked questions

Is every chatbot high-risk?

No. Classification follows intended purpose and legal conditions, not the mere use of a language model. A chatbot may still require disclosure that a person is interacting with AI. Use in employment, education or access to essential services can lead to a different analysis.

Are small businesses exempt?

The Act includes some lighter measures for smaller entities but no blanket SME exemption. Prohibitions, AI literacy and role-specific obligations can still apply. The Omnibus agreement expands some simplifications; check the final text and eligibility conditions.

Should employee use of ChatGPT or Claude appear in the inventory?

When a tool supports business processes or receives organisational data, inventory enables assessment of risk, contract and permitted data. Not every experiment has equal priority, but no visibility means no way to identify uses affecting customers, employees or decisions.

Does AI literacy require a specific certificate?

The Act does not create one universal employee certificate. Measures should provide an appropriate competence level based on knowledge, experience, context and affected persons. Evidence can include role-based training, instructions, exercises and assessment.

Is a compliant GPAI supplier enough for the deployer?

No. The supplier addresses its obligations; the business remains responsible for its use, data, integrations, oversight and other law. A documented model can still sit inside an application with broken authorisation or an impermissible workflow.

Where should a small team start?

Begin with a short inventory and triage. Prioritise systems affecting people, decisions, confidential data and irreversible operations for legal and technical review. Lower-risk productivity tools can use a lighter process while retaining baseline data and security controls.

How Breachroad can help

Breachroad connects technical AI security with practical governance. We can map systems and suppliers, develop threat models, assess LLM, RAG and agent controls and provide evidence for risk management. We do not replace legal counsel, but we test whether declared technical safeguards actually work.

If your organisation deploys generative AI or is preparing for the 2026–2028 requirements, review our AI security services or book a call.


Primary sources: AI Act — Regulation 2024/1689, European Commission — AI Act and current timeline, AI Act Service Desk, Commission GPAI guidance.

SHARE / COPY